Welcome!

Security Authors: Trevor Parsons, Sandeep Kumar, Bob Gourley, John Savageau, Pat Romanski

Related Topics: Cloud Expo, Security, GovIT

Cloud Expo: Article

Is Cloud Computing for Real?

Summary of Session by CIO of the National Reconnaissance Office at Cloud Expo New York

In October 2009, Enterprise Cloud Computing was considered bleeding edge technology by many but there was something that seemed different about its value potential and adoption rate. For CIOs, it seemed a chance to provision affordable infrastructure quickly, alleviating delays to mission critical deliveries. Federal CIOs interest in Enterprise Cloud Computing was limited to innovators and early adopters. Two years later, where does Enterprise Cloud Computing stand? Is it for real?



Today, Cloud Computing is on the Gartner® technology hype curve in the “peak of inflated expectations” category. Its placement on the curve—even though we all should prepare for the dreaded “trough of disillusionment” dip—indicates Cloud Computing is, indeed, for real. There are other indicators of note also. CIOs across the board are focused on the success Cloud Computing can deliver. Vendors are sparring with each other to obtain space in Gartner’s Magic Quadrant. The Federal CIO has issued a “Cloud First” policy and published the first Federal Cloud Computing Strategy. And, it’s been featured in the hit comic strip Dilbert—a pop culture indicator worth noting!

Federal agencies need IT solutions that can handle current missions—from supporting counter-terrorism to combating proliferation of weapons of mass destruction--and we need IT that can handle global surge demands based on fluctuating world events and natural disasters. Federal IT must be efficiently adaptable and properly affordable to meet evolving mission needs. It must be capable of keeping pace with the exponential growth of data, including the increasing complexities of maintaining legal and regulatory compliance of information management and assurance.

As a CIO, building your cloud strategy can be confusing as there are many options to consider before making a decision. Cloud Computing can deliver within a variety of characteristics. Each CIO will need to consider the characteristics of primary importance in order to properly center a strategy. For example, determining your needs for rapid elasticity, on-demand self-service, global access, and payment options will be necessary to develop the right strategy. The second consideration for a CIO is just how far up the stack she wants to go. Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) each deliver different features and capabilities for your business. You can develop a plan that includes some or all of the Services. Finally, a CIO needs to think about the deployment model(s) that best fit her business (Public, Private, Community, and Hybrid).

Cloud Computing isn’t perfect; there are concerns to manage and mistakes to avoid. The number one concern remains Security and that’s given rise to Enterprise Cloud Computing deployments and private clouds. But, there are other concerns also such as the skill set of your workforce, requirements for compliance verification, legacy baseline migration, and costs. For example, depending on the percentage of your legacy that can successfully transition to Cloud, your cost-benefit equation may not provide sufficient return for the investment.

Common mistakes to avoid include: assuming Cloud Computing is for everything; planning for a “light switch” migration from legacy to new; selecting only one vendor and creating early lock-in; underestimating the cultural change required by your own IT team; and implementing a bunch of mini- clouds in your existing data closets.

We’ve spent 18 months developing the National Reconnaissance Office (NRO) IT strategy and roadmap; we gave it a lot of thought but it is just an example and not the only way to move forward. Our cloud delivery model will be private first and then a hybrid of private and community (with our Intelligence Community colleagues). We’re moving our way up the stack starting with IaaS and PaaS first, then SaaS. And, we are focused on a phased revolutionary approach—building a new environment as a green field.

Our planning has highlighted the need to focus attention on management of the NRO Cloud. Defining specific roles and responsibilities, articulating cloud service level agreements between the provider and users, adjusting organizational constructs to fit the Cloud business model, and streamlining configuration control processes to meet the rapid timelines of provisioning must all be addressed if success is to be achieved. Our planning also indicated the NRO mission would not be served by a CPU-based commodity cloud alone. We also need a high-performance cloud that is GPU-based and we are learning there are industry gaps in this area.

The NRO Cloud strategy won’t be too different from how other Federal agencies adopt Cloud Computing. Most agencies processing classified information are focused on private clouds versus public clouds for security and information management/assurance reasons. Over time, though, I believe federal community clouds will emerge, as will private hybrid clouds, which allow agencies to maintain a private space as well as take advantage of federal community clouds.

The NRO Cloud will be implemented in four phases over the course of 6 years. It’s a complex migration necessarily paced to meet federal budget processes, existing acquisition commitments, and mission service imperatives.

  • Phase 1 – Test It. We have multiple small cloud pilots ongoing covering commodity/utility cloud, high performance cloud, and big data cloud. We are focused on streamlining information assurance compliance, developing appropriate policies and processes, and defining standards.
  • Phase 2 – Prove It. In this phase, we will merge successful elements from Phase 1, finalize policies, prototype management and governance changes necessary for cloud provisioning models, refine standards, realign programs as needed, and ensure enterprise foundation capabilities meet mission demands.
  • Phase 3 – Use It. Scaled deployment of the enterprise Cloud will occur. Applications will develop specific transition and migration plans generally aligned with planned refresh cycles. Service management processes and new centralized information assurance approaches will be refined for long-term success.
  • Phase 4 – Exploit It. The NRO Cloud will emerge as the primary Enterprise Infrastructure Services Provider with robust measures of effectiveness, performance accountability, and service transparency. New mission and business applications will emerge through innovations in Cloud Computing and federation with the IC Cloud will be achieved moving the NRO into a hybrid environment.

In summary, the time for Cloud Computing is now. All of the indicators are in place to suggest a rapid and successful migration to this newest generation of IT architecture. It is not a one-size-fits-all migration. CIOs will need to spend time exploring Cloud Computing solutions to find the combination that best responds to specific mission and business needs. Maintaining awareness of the concerns and mistakes is absolutely necessary and security remains the top concern. Security is a huge focus for IT vendors and creative, robust solutions will be constantly emerging to reduce concerns. Large organizations will increasingly turn to Enterprise Cloud Computing strategies to achieve efficiencies of Cloud Computing while reducing risks of exposure for intellectual property, customer privacy, and competitive strategies.

More Stories By Jill Tummler Singer

Jill Tummler Singer is CIO for the National Reconnaissance Office (NRO)- which as part of the 16-member Intelligence Community plays a primary role in achieving information superiority for the U.S. Government and Armed Forces. A DoD agency, the NRO is staffed by DoD and CIA personnel. It is funded through the National Reconnaissance Program, part of the National Foreign Intelligence Program.

Prior to joining the NRO, Singer was Deputy CIO at the Central Intelligence Agency (CIA), where she was responsible for ensuring CIA had the information, technology, and infrastructure necessary to effectively execute its missions. Prior to her appointment as Deputy CIO, she served as the Director of the Diplomatic Telecommunications Service (DTS), United States Department of State, and was responsible for global network services to US foreign missions.

Singer has served in several senior leadership positions within the Federal Government. She was the head of Systems Engineering, Architecture, and Planning for CIA's global infrastructure organization. She served as the Director of Architecture and Implementation for the Intelligence Community CIO and pioneered the technology and management concepts that are the basis for multi-agency secure collaboration. She also served within CIA’s Directorate of Science and Technology.

Comments (1) View Comments

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


Most Recent Comments
Elad Israeli 06/20/11 08:48:00 AM EDT

I can relate to many points you list here. I come from the business intelligence space, where the Cloud and SaaS are way overly hyped - mainly due to some startups in the space.

http://tinyurl.com/saas-bi

@ThingsExpo Stories
The Internet of Things (IoT) promises to evolve the way the world does business; however, understanding how to apply it to your company can be a mystery. Most people struggle with understanding the potential business uses or tend to get caught up in the technology, resulting in solutions that fail to meet even minimum business goals. In his session at @ThingsExpo, Jesse Shiah, CEO / President / Co-Founder of AgilePoint Inc., showed what is needed to leverage the IoT to transform your business. He discussed opportunities and challenges ahead for the IoT from a market and technical point of vie...
IoT is still a vague buzzword for many people. In his session at @ThingsExpo, Mike Kavis, Vice President & Principal Cloud Architect at Cloud Technology Partners, discussed the business value of IoT that goes far beyond the general public's perception that IoT is all about wearables and home consumer services. He also discussed how IoT is perceived by investors and how venture capitalist access this space. Other topics discussed were barriers to success, what is new, what is old, and what the future may hold. Mike Kavis is Vice President & Principal Cloud Architect at Cloud Technology Pa...
Dale Kim is the Director of Industry Solutions at MapR. His background includes a variety of technical and management roles at information technology companies. While his experience includes work with relational databases, much of his career pertains to non-relational data in the areas of search, content management, and NoSQL, and includes senior roles in technical marketing, sales engineering, and support engineering. Dale holds an MBA from Santa Clara University, and a BA in Computer Science from the University of California, Berkeley.
The Internet of Things (IoT) is rapidly in the process of breaking from its heretofore relatively obscure enterprise applications (such as plant floor control and supply chain management) and going mainstream into the consumer space. More and more creative folks are interconnecting everyday products such as household items, mobile devices, appliances and cars, and unleashing new and imaginative scenarios. We are seeing a lot of excitement around applications in home automation, personal fitness, and in-car entertainment and this excitement will bleed into other areas. On the commercial side, m...
"People are a lot more knowledgeable about APIs now. There are two types of people who work with APIs - IT people who want to use APIs for something internal and the product managers who want to do something outside APIs for people to connect to them," explained Roberto Medrano, Executive Vice President at SOA Software, in this SYS-CON.tv interview at Cloud Expo, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
An entirely new security model is needed for the Internet of Things, or is it? Can we save some old and tested controls for this new and different environment? In his session at @ThingsExpo, New York's at the Javits Center, Davi Ottenheimer, EMC Senior Director of Trust, reviewed hands-on lessons with IoT devices and reveal a new risk balance you might not expect. Davi Ottenheimer, EMC Senior Director of Trust, has more than nineteen years' experience managing global security operations and assessments, including a decade of leading incident response and digital forensics. He is co-author of t...
Performance is the intersection of power, agility, control, and choice. If you value performance, and more specifically consistent performance, you need to look beyond simple virtualized compute. Many factors need to be considered to create a truly performant environment. In his General Session at 15th Cloud Expo, Harold Hannon, Sr. Software Architect at SoftLayer, discussed how to take advantage of a multitude of compute options and platform features to make cloud the cornerstone of your online presence.
SYS-CON Media announced that Splunk, a provider of the leading software platform for real-time Operational Intelligence, has launched an ad campaign on Big Data Journal. Splunk software and cloud services enable organizations to search, monitor, analyze and visualize machine-generated big data coming from websites, applications, servers, networks, sensors and mobile devices. The ads focus on delivering ROI - how improved uptime delivered $6M in annual ROI, improving customer operations by mining large volumes of unstructured data, and how data tracking delivers uptime when it matters most.
DevOps Summit 2015 New York, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that it is now accepting Keynote Proposals. The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete at launch. DevOps may be disruptive, but it is essential.
Almost everyone sees the potential of Internet of Things but how can businesses truly unlock that potential. The key will be in the ability to discover business insight in the midst of an ocean of Big Data generated from billions of embedded devices via Systems of Discover. Businesses will also need to ensure that they can sustain that insight by leveraging the cloud for global reach, scale and elasticity.
The Internet of Things will greatly expand the opportunities for data collection and new business models driven off of that data. In her session at @ThingsExpo, Esmeralda Swartz, CMO of MetraTech, discussed how for this to be effective you not only need to have infrastructure and operational models capable of utilizing this new phenomenon, but increasingly service providers will need to convince a skeptical public to participate. Get ready to show them the money!
How do APIs and IoT relate? The answer is not as simple as merely adding an API on top of a dumb device, but rather about understanding the architectural patterns for implementing an IoT fabric. There are typically two or three trends: Exposing the device to a management framework Exposing that management framework to a business centric logic Exposing that business layer and data to end users. This last trend is the IoT stack, which involves a new shift in the separation of what stuff happens, where data lives and where the interface lies. For instance, it's a mix of architectural styles ...
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is now open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
The 3rd International Internet of @ThingsExpo, co-located with the 16th International Cloud Expo - to be held June 9-11, 2015, at the Javits Center in New York City, NY - announces that its Call for Papers is now open. The Internet of Things (IoT) is the biggest idea since the creation of the Worldwide Web more than 20 years ago.
"There is a natural synchronization between the business models, the IoT is there to support ,” explained Brendan O'Brien, Co-founder and Chief Architect of Aria Systems, in this SYS-CON.tv interview at the 15th International Cloud Expo®, held Nov 4–6, 2014, at the Santa Clara Convention Center in Santa Clara, CA.
The Internet of Things will put IT to its ultimate test by creating infinite new opportunities to digitize products and services, generate and analyze new data to improve customer satisfaction, and discover new ways to gain a competitive advantage across nearly every industry. In order to help corporate business units to capitalize on the rapidly evolving IoT opportunities, IT must stand up to a new set of challenges. In his session at @ThingsExpo, Jeff Kaplan, Managing Director of THINKstrategies, will examine why IT must finally fulfill its role in support of its SBUs or face a new round of...
The BPM world is going through some evolution or changes where traditional business process management solutions really have nowhere to go in terms of development of the road map. In this demo at 15th Cloud Expo, Kyle Hansen, Director of Professional Services at AgilePoint, shows AgilePoint’s unique approach to dealing with this market circumstance by developing a rapid application composition or development framework.

ARMONK, N.Y., Nov. 20, 2014 /PRNewswire/ --  IBM (NYSE: IBM) today announced that it is bringing a greater level of control, security and flexibility to cloud-based application development and delivery with a single-tenant version of Bluemix, IBM's platform-as-a-service. The new platform enables developers to build ap...

Advanced Persistent Threats (APTs) are increasing at an unprecedented rate. The threat landscape of today is drastically different than just a few years ago. Attacks are much more organized and sophisticated. They are harder to detect and even harder to anticipate. In the foreseeable future it's going to get a whole lot harder. Everything you know today will change. Keeping up with this changing landscape is already a daunting task. Your organization needs to use the latest tools, methods and expertise to guard against those threats. But will that be enough? In the foreseeable future attacks w...
As enterprises move to all-IP networks and cloud-based applications, communications service providers (CSPs) – facing increased competition from over-the-top providers delivering content via the Internet and independently of CSPs – must be able to offer seamless cloud-based communication and collaboration solutions that can scale for small, midsize, and large enterprises, as well as public sector organizations, in order to keep and grow market share. The latest version of Oracle Communications Unified Communications Suite gives CSPs the capability to do just that. In addition, its integration ...